Cache Clash: How CDN Misconfigurations Let Me Hijack Thousands of User Sessions
文章描述了作者通过利用CDN配置错误进行缓存投毒攻击的过程,成功实现会话劫持和数据泄露,并展示了完整的PoC。作者以一种幽默的方式讲述了如何通过CDN漏洞同时控制数千个用户会话的经历。 2026-1-5 13:14:16 Author: infosecwriteups.com(查看原文) 阅读量:8 收藏

Iski

Free link 🎈

Hey there!😁

Press enter or click to view image in full size

Image by AI

From discovering cache poisoning to session hijacking, data leakage, and becoming every user simultaneously. Join my journey of exploiting CDN misconfigurations with advanced cache poisoning techniques. Full PoC included. ☕

You know that feeling when you walk into a coffee shop and accidentally pick up someone else’s identical laptop, only to discover it’s unlocked with all their banking tabs open? 💻 That was me — but instead of a coffee shop, it was a multi-million dollar company’s CDN, and instead of one laptop, I could access thousands of user sessions simultaneously. My roommate thought I’d finally lost it when I started yelling “I’m everyone!” at my monitor.

It all started when I noticed cdn.corporate-app.com serving static assets. As I browsed the application, I spotted something peculiar in the network tab...


文章来源: https://infosecwriteups.com/cache-clash-how-cdn-misconfigurations-let-me-hijack-thousands-of-user-sessions-52e09bc0b0a2?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh